⏳ This skill is pending AI review.
Scores will appear once the review pipeline completes.
code-review
Pre-deploy code review. Analyzes diffs or entire files for SQL safety, N+1 queries, race conditions, trust boundary violations, error handling gaps, and structural issues. Auto-fixes obvious problems, escalates ambiguous ones. Use when asked to "review this code", "review before deploy", "pre-landing review", "check this diff", "audit this file", or before any deploy/push. Proactively suggest when user is about to deploy or merge.
Choose how to use this skill
You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.
1. Native installer
This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.
Do not guess an installer command or replace an existing version without reviewing the diff.
2. Complete package recommended
Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.
No complete ProSkills package is published for this listing yet.3. Prompt-only
Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.
Need only the instruction file?
Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.
No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.
// RATINGS
Not yet listed on ClawHub or SkillsMP
// README
🛠️ OpenClaw Skills — Software Quality Toolkit
Four skills that make AI agents build better software. Built for OpenClaw, the open-source AI agent platform.
Inspired by real production experience deploying AI agents + ideas from gstack. Zero dependencies, pure methodology.
Skills
| Skill | What it does | When it triggers |
|---|---|---|
| code-review | Pre-deploy review with P0→P3 priorities, auto-fix | "review this", "check before deploy" |
| debugger | Root cause investigation — no fix without proof | "debug this", "why is this broken" |
| security-audit | OWASP Top 10 + STRIDE + secrets scan | "security audit", "check for secrets" |
| kapilot | Autonomous dev pipeline — plan to code while you sleep | "kapilot", "build while I sleep" |
How They Work Together
You have a plan
│
▼
┌──────────┐ Autonomous? ──▶ Kapilot (orchestrates everything)
│ Build │ │
│ Code │ │ Kapilot runs these automatically:
└────┬─────┘ │ ├── code-review (R1)
│ │ ├── security-audit (R2)
▼ │ └── debugger (when tests fail)
┌──────────┐ │
│ Review │◀────────┘
│ Code │──▶ code-review
└────┬─────┘
│
▼
┌──────────┐
│ Security │──▶ security-audit
│ Check │
└────┬─────┘
│
▼
┌──────────┐
│ Bug? │──▶ debugger
│ Debug │
└────┬─────┘
│
▼
Ship it 🚀
Individually: Each skill works standalone. Ask for a review, debug a bug, or run a security audit anytime.
Together via Kapilot: The autonomous pipeline uses all three as quality gates. Code review (R1) → Security scan (R2) → Debug if broken → Commit → Next phase.
Installation
OpenClaw (recommended)
Copy the skill folders to your OpenClaw workspace:
# Clone this repo
git clone https://github.com/kapitecsoluciones/openclaw-skills.git
# Copy skills to your workspace
cp -r openclaw-skills/code-review ~/.openclaw/workspace/skills/
cp -r openclaw-skills/debugger ~/.openclaw/workspace/skills/
cp -r openclaw-skills/security-audit ~/.openclaw/workspace/skills/
cp -r openclaw-skills/kapilot ~/.openclaw/workspace/skills/
OpenClaw auto-discovers skills in ~/.openclaw/workspace/skills/. No config needed.
Claude Code
These work with any agent that reads SKILL.md files. For Claude Code, drop them in your project's .claude/skills/ directory.
Other Agents
Each skill is a self-contained Markdown file. Any agent that can read instructions from a file can use them. No binaries, no config files, no lock-in.
Quick Start
Code Review
Just ask your agent to review before deploying:
"Review the code before I deploy"
It will:
- Identify changed files (via git diff or specified files)
- Run automated checks (syntax, secrets, security patterns)
- Analyze each file for P0 (blocks deploy) through P3 (nice to have) issues
- Auto-fix obvious problems (P0 + simple P1)
- Give a verdict: ✅ SHIP IT / ⚠️ FIX THEN SHIP / 🛑 DO NOT SHIP
Debugger
When something breaks:
"Debug why login returns 500"
It will:
- Investigate — Reproduce, read logs, check timeline
- Analyze — Narrow scope, read code, check assumptions
- Hypothesize — State root cause, prove it
- Implement — Minimal fix, fix siblings, verify
Iron Law: No fix without confirmed root cause. If it can't explain the bug in one sentence, it goes back to investigating.
Security Audit
Two modes:
"Quick security check" → 5 min, high-confidence findings only
"Deep security audit" → 20 min, OWASP Top 10 + STRIDE + dependencies
Checks: hardcoded secrets (including git history), SQL injection, XSS, auth bypass, CORS misconfiguration, debug mode in production, default credentials, outdated dependencies.
Kapilot (Autonomous Pipeline)
Give it a plan file and let it run:
"Activate kapilot with PLAN.md"
It sets up a cron job that:
- Reads the current phase from the plan
- Implements it
- Reviews (code-review + security-audit)
- Checks scope (did it build what the plan says?)
- Verifies (build + tests pass)
- Commits with detailed message
- Advances to next phase
- Notifies you
Runs every 15-30 minutes. You wake up to commits.
Stop conditions: All phases done, critical security issue, build fails 3x, or you say stop.
Design Principles
-
Methodology over code. These skills are instructions, not programs. They teach the agent how to think about quality, not just what commands to run.
-
Composable. Each skill works alone. Together they're a pipeline. Mix and match.
-
No dependencies. Pure Markdown + standard CLI tools (grep, git, curl). No npm packages, no binaries, no config files.
-
Fail loud. When something's wrong, stop and tell the human. Don't bury errors in logs.
-
Evidence-based. Every finding has a file:line reference. Every bug fix has a root cause. Every security issue has a concrete grep result.
Contributing
PRs welcome. Keep skills as pure Markdown methodology — no binaries, no build steps, no telemetry.
License
MIT — Use however you want.
Built by Kapitec Soluciones 🤙
// HOW IT'S BUILT
KEY FILES